Skip to content
Legal

Privacy Policy

Last updated: August 1, 2026

1. Overview

Ion (“we”, “us”, “our”) operates the Ion AI workspace and related services (the “Service”). This Privacy Policy explains how we collect, use, and protect your data when you use the Service.

We take privacy seriously. We never train foundation models on your data, we minimize what we collect, and we give you control over your information.

2. Data we collect

2.1 Data you provide

  • Account information: name, email address, company name.
  • Workspace content: documents, tickets, messages, and other content you create or upload.
  • Integration data: data synced from connected third-party services (Slack, GitHub, Linear, etc.).
  • Communications: emails and support requests you send us.

2.2 Data collected automatically

  • Usage data: pages visited, features used, time spent, IP address, browser type.
  • Device data: device type, operating system, unique device identifiers.
  • Cookies and similar technologies: for authentication, preferences, and analytics.

3. How we use your data

  • To provide, operate, and maintain the Service.
  • To improve the Service — including training workspace-specific retrieval models (never foundation models).
  • To communicate with you about your account, updates, and security.
  • To detect, prevent, and address technical issues, fraud, and abuse.
  • To comply with legal obligations.

4. Data sharing

We do not sell your data. We share it only in these circumstances:

  • Service providers: sub-processors who help us operate (hosting, email, analytics). List available at /security.
  • Legal compliance: when required by law, court order, or to protect our rights and safety.
  • Business transfers: in connection with a merger, acquisition, or asset sale — with notice to you.

5. Data retention

We retain your data for as long as your account is active. After account deletion:

  • Workspace content: deleted within 30 days.
  • Backups: purged within 90 days.
  • Usage logs: aggregated and anonymized after 13 months.
  • Legal holds: retained only if required by law.

6. Your rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you have the right to:

  • Access the data we hold about you.
  • Correct inaccurate data.
  • Delete your data (right to erasure).
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time.

To exercise these rights, email privacy@ion.app. We respond within 30 days.

7. Security

We protect your data with industry-standard measures:

  • AES-256 encryption at rest, TLS 1.3 in transit.
  • SOC 2 Type II certified. Report available under NDA.
  • Regular penetration testing by independent firms.
  • Strict access controls — engineers don't have default access to customer data.

See our Security page for full details.

8. International transfers

Your data may be processed in countries other than your own. We use Standard Contractual Clauses and other appropriate safeguards for cross-border transfers. Enterprise customers can choose data residency in US, EU, or APAC regions.

9. Children's privacy

The Service is not directed to children under 16. We do not knowingly collect data from children. If you believe we have, please contact us immediately.

10. Changes to this policy

We may update this policy from time to time. We'll notify you of material changes by email and post a notice in the app at least 30 days before they take effect.

11. Contact

Questions about privacy? Email privacy@ion.app or write to us at: Ion Inc., 548 Market St, San Francisco, CA 94104.